CVE-2019-1026 is an elevation of privilege vulnerability in the Windows Audio Service affecting Windows 10, Windows Server 2016, and Windows Server 2019. An attacker could exploit this by running a specially crafted application, gaining elevated privileges. While not allowing arbitrary code execution independently, it could be chained with other vulnerabilities for greater impact. The vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring low privileges, and no user interaction, leading to high confidentiality, integrity, and availability impacts. Its EPSS score is very low, suggesting a low probability of exploitation. There is no evidence of active exploitation, and no public exploit code exists in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one article mentioning it as part of a larger patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.